{"id":17665,"date":"2026-09-21T10:50:28","date_gmt":"2026-09-21T10:50:28","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=17665"},"modified":"2026-09-21T10:50:28","modified_gmt":"2026-09-21T10:50:28","slug":"fortinet-nse5_sse_ad-7-6-practice-test-questions-and-exam-dumps-part13-q241-260","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/fortinet-nse5_sse_ad-7-6-practice-test-questions-and-exam-dumps-part13-q241-260\/","title":{"rendered":"Fortinet NSE5_SSE_AD-7.6 Practice Test Questions and Exam Dumps Part13 Q241-260"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/nse5-sse-ad-7-6-exam-dumps\"><b>Fortinet NSE5_SSE_AD-7.6 Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 241<\/b><\/h3>\n<p><b>Which SSE capability provides application-specific access to private resources based on identity and security context?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust Network Access provides controlled access to private applications according to identity and contextual security information. Instead of granting users broad access to an internal network, ZTNA can authorize access to individual applications based on configured policies. These policies may consider user identity, authentication status, device posture, and other conditions. DNS Security protects domain requests, DLP protects sensitive information, and CASB focuses on cloud applications. ZTNA therefore provides the application-level access model required when organizations want to implement least privilege and reduce unnecessary exposure of internal resources.<\/span><\/p>\n<h3><b>Question 242<\/b><\/h3>\n<p><b>Which SSE service is responsible for filtering and controlling general internet web traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Web Gateway provides security inspection and policy enforcement for users accessing internet websites and web applications. It can support functions such as URL filtering, web category controls, malware protection, and application-based policies. SWG allows organizations to centrally control internet access regardless of where users connect. CASB is focused on cloud application security, ZTNA controls private application access, and DLP focuses on sensitive data. Therefore, Secure Web Gateway is the appropriate SSE service for filtering and controlling general internet web traffic.<\/span><\/p>\n<h3><b>Question 243<\/b><\/h3>\n<p><b>Which capability provides visibility and control over cloud applications such as SaaS services?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Access Security Broker provides visibility and security controls for cloud applications. CASB can help organizations identify cloud services being used by employees, monitor activity, and apply policies according to organizational requirements. This can also help identify unsanctioned applications and manage the risks associated with cloud usage. DLP protects sensitive information, DNS Security protects domain requests, and DHCP provides network configuration. CASB is therefore the capability most directly associated with visibility and policy enforcement for SaaS and other cloud applications.<\/span><\/p>\n<h3><b>Question 244<\/b><\/h3>\n<p><b>Which security principle restricts users to only the resources required for their assigned responsibilities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Least privilege<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Implicit trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Least privilege requires that users receive only the permissions and resources needed to perform their authorized tasks. This reduces unnecessary access and limits the potential impact of compromised credentials or endpoints. In a Zero Trust architecture, least privilege can be applied by granting access to specific applications instead of an entire network. Full trust, open access, and implicit trust allow broader access and do not follow the same restrictive approach. Least privilege is therefore a fundamental security principle for reducing exposure while still allowing users to perform legitimate business activities.<\/span><\/p>\n<h3><b>Question 245<\/b><\/h3>\n<p><b>Which authentication factor is an example of something the user possesses?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PIN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Fingerprint<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Hardware security token<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A hardware security token is a possession factor because it is something the user has. Authentication factors are commonly categorized as knowledge, possession, and inherence. Passwords and PINs are knowledge factors, while a fingerprint is a biometric factor representing something the user is. A hardware token can be combined with another factor to provide multifactor authentication. Using multiple factor categories strengthens authentication because possession of one credential alone is not necessarily sufficient to gain access to protected resources.<\/span><\/p>\n<h3><b>Question 246<\/b><\/h3>\n<p><b>Which capability can detect sensitive data and take an action such as blocking or logging the transfer?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Data Loss Prevention can inspect supported traffic for sensitive information based on configured patterns, rules, classifications, or dictionaries. When protected content is detected, DLP policies can specify actions such as allowing, blocking, logging, or generating alerts. This helps organizations protect confidential business information, personal data, intellectual property, and other sensitive content. Application Control identifies applications, DNS Security protects domain requests, and ZTNA provides private application access. DLP is therefore the capability specifically designed to identify sensitive information and control its transmission.<\/span><\/p>\n<h3><b>Question 247<\/b><\/h3>\n<p><b>Which feature can apply security policies according to the actual application identified in traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS caching<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Application Control identifies applications within network traffic and allows administrators to create application-specific security policies. This provides more granular visibility than relying only on IP addresses or ports. Organizations can use application control to permit, block, monitor, or restrict services such as streaming, messaging, file sharing, or other applications. DHCP provides network configuration, NTP synchronizes system time, and DNS caching stores domain-resolution information. Application Control is therefore the appropriate feature for identifying applications and applying policies based on the actual service detected in traffic.<\/span><\/p>\n<h3><b>Question 248<\/b><\/h3>\n<p><b>Which security service can block DNS requests for domains classified as malicious?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DNS Security can inspect DNS requests and compare domain destinations against threat intelligence and configured security policies. If a requested domain is associated with malware, phishing, command-and-control infrastructure, or another prohibited category, the request can be blocked or redirected. This provides an early security control before users establish a full connection to a harmful destination. CASB manages cloud applications, DLP protects sensitive information, and ZTNA controls private application access. DNS Security is therefore the appropriate service for blocking malicious domain requests.<\/span><\/p>\n<h3><b>Question 249<\/b><\/h3>\n<p><b>Which feature can control access to websites based on categories such as malware, phishing, or inappropriate content?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Web filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NTP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Web filtering allows administrators to control access to websites according to categories, reputation, or configured URLs. It can be used to block websites associated with malware, phishing, inappropriate content, gambling, or other restricted categories. This function is commonly provided through Secure Web Gateway capabilities. DHCP provides network addressing, NAT performs address translation, and NTP synchronizes clocks. Web filtering is therefore the appropriate security feature when an organization needs to enforce web access policies based on content or security categories.<\/span><\/p>\n<h3><b>Question 250<\/b><\/h3>\n<p><b>Which capability can evaluate the security condition of an endpoint before granting access to a private application?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">URL Filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Device Posture<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Caching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traffic Shaping<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Device posture provides information about the security and compliance state of an endpoint. In a Zero Trust environment, this information can be evaluated as part of an access policy before a user receives access to a protected application. Depending on the available integration, posture may include endpoint protection status, operating system state, compliance information, or other security attributes. URL filtering manages websites, DNS caching stores resolution information, and traffic shaping controls bandwidth. Device posture is therefore the relevant capability for evaluating endpoint security as part of application authorization.<\/span><\/p>\n<h3><b>Question 251<\/b><\/h3>\n<p><b>Which SSE architecture delivers cloud-based security services to users working from different locations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Security Service Edge<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Standalone DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Traditional LAN switching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Local-only routing<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Security Service Edge is an architecture designed to provide cloud-delivered security services to distributed users and locations. Depending on the deployment, SSE can include Secure Web Gateway, Zero Trust Network Access, CASB, DLP, and other security capabilities. This model is useful for remote employees, branch users, and mobile workers because security policies can be enforced through cloud infrastructure. DHCP and LAN switching provide networking services, while local-only routing does not represent the integrated cloud security architecture. SSE is therefore the appropriate architecture for distributed cloud-delivered security.<\/span><\/p>\n<h3><b>Question 252<\/b><\/h3>\n<p><b>Which capability helps discover cloud applications that have not been approved by an organization?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CASB provides visibility into cloud application usage and can help organizations discover unsanctioned or unapproved SaaS services. Identifying these applications allows security teams to evaluate risks related to data protection, privacy, compliance, and unauthorized cloud usage. Administrators can then create policies to permit, monitor, restrict, or block applications based on organizational requirements. DNS Security protects domain requests, DLP focuses on sensitive information, and ZTNA controls private application access. CASB is therefore the capability most directly associated with discovering and managing unapproved cloud applications.<\/span><\/p>\n<h3><b>Question 253<\/b><\/h3>\n<p><b>Which authentication method requires two or more different authentication factors?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Password-only authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Single sign-on<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Multifactor authentication<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Anonymous authentication<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Multifactor authentication requires two or more authentication factors, typically from different categories such as knowledge, possession, and inherence. For example, a password can be combined with a hardware token or biometric factor. This provides stronger identity protection because compromising one factor alone may not be enough to gain access. Password-only authentication uses a single factor, while anonymous authentication does not provide equivalent identity verification. MFA is therefore the authentication method designed to require multiple factors for a stronger authentication process.<\/span><\/p>\n<h3><b>Question 254<\/b><\/h3>\n<p><b>Which SSE component protects internet users by inspecting web traffic and applying security policies?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Web Gateway provides inspection and policy enforcement for users&#8217; internet-bound web traffic. It can support URL filtering, web category controls, malware protection, application identification, and other security features. This allows organizations to apply consistent security policies to users regardless of where they connect. CASB focuses on cloud application security, DLP protects sensitive data, and ZTNA controls access to private applications. Secure Web Gateway is therefore the primary SSE component for protecting users while they access internet websites and web applications.<\/span><\/p>\n<h3><b>Question 255<\/b><\/h3>\n<p><b>Which capability can provide access to private applications without exposing the applications directly to the public internet?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust Network Access can provide controlled access to private applications while keeping those applications from being broadly exposed to the public internet. Users are authenticated and evaluated against access policies before being allowed to connect to specific applications. This approach reduces attack surface and supports least-privilege access. DLP protects sensitive information, CASB manages cloud applications, and DNS Security protects domain requests. ZTNA is therefore the appropriate technology for providing secure application access without requiring public exposure of internal applications.<\/span><\/p>\n<h3><b>Question 256<\/b><\/h3>\n<p><b>Which capability can identify sensitive information and generate an alert when a policy violation occurs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Application Control<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">SWG<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">DLP can detect sensitive information within supported traffic and apply configured actions when policy conditions are met. These actions may include logging, generating an alert, blocking the transaction, or allowing it while recording the event. This capability helps organizations identify potential data leakage and protect confidential or regulated information. Application Control identifies applications, DNS Security evaluates domain requests, and SWG protects web traffic. DLP is therefore the appropriate capability for detecting sensitive information and alerting administrators when a data protection policy is violated.<\/span><\/p>\n<h3><b>Question 257<\/b><\/h3>\n<p><b>Which principle assumes that access must be explicitly verified rather than automatically trusted based on network location?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Open access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Zero Trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Full trust<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Perimeter-only trust<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Zero Trust requires access to be explicitly verified rather than automatically granted because a user or device is connected to a trusted network. Access decisions can evaluate identity, authentication, device posture, application, and other contextual factors. This approach reduces reliance on the traditional network perimeter and limits unnecessary access. Open access and full trust allow broader permissions, while perimeter-only trust relies primarily on network boundaries. Zero Trust therefore represents the security principle in which trust is not automatically granted based on network location.<\/span><\/p>\n<h3><b>Question 258<\/b><\/h3>\n<p><b>Which capability allows security policies to be based on authenticated user identity?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NAT<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static Routing<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Identity-based policy<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 4<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Identity-based policies allow security controls to be associated with authenticated users, groups, roles, or other identity attributes. This provides more granular access control than relying only on IP addresses or network locations. For example, administrators can give different web or application access to employees, contractors, and privileged users. NAT translates network addresses, DHCP provides network configuration, and static routing controls traffic paths. Identity-based policy is therefore the capability that allows security decisions to directly reflect the authenticated identity of the user.<\/span><\/p>\n<h3><b>Question 259<\/b><\/h3>\n<p><b>Which service can enforce security controls for cloud applications based on users and activities?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DNS Security<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DHCP<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">CASB provides cloud application visibility and security controls that can be applied according to users, applications, activities, and other policy conditions. This helps organizations govern cloud services and manage risks associated with SaaS usage. Administrators can monitor activity and create controls for sanctioned or unsanctioned applications based on organizational requirements. DNS Security focuses on domain requests, DLP protects sensitive information, and DHCP provides network configuration. CASB is therefore the most appropriate service for applying security controls to cloud application activity.<\/span><\/p>\n<h3><b>Question 260<\/b><\/h3>\n<p><b>Which SSE capability provides centralized policy enforcement for users accessing web resources from remote locations?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">DLP<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ZTNA<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secure Web Gateway<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CASB<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secure Web Gateway provides centralized security policy enforcement for users accessing internet web resources. In a cloud-delivered SSE architecture, remote users can receive consistent controls such as URL filtering, web category restrictions, malware protection, and application policies without needing to be physically located at a corporate site. DLP protects sensitive information, ZTNA controls private application access, and CASB manages cloud applications. Secure Web Gateway is therefore the appropriate SSE capability for centrally securing web access for remote and distributed users.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Fortinet NSE5_SSE_AD-7.6 Exam Dumps and Practice Test Dumps. &nbsp; Question 241 Which SSE capability provides application-specific access to private resources based on identity and security context? DNS Security DLP CASB ZTNA Correct Answer: 4 Explanation Zero Trust Network Access provides controlled access to private applications according to identity and contextual security information. Instead [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17665"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=17665"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17665\/revisions"}],"predecessor-version":[{"id":17666,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/17665\/revisions\/17666"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=17665"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=17665"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=17665"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}